← Vulnerability feed

Vulnerability record · CVE-2016-0956 · published 10 February 2016

CVE-2016-0956: Apache Sling Servlets Post information disclosure in Adobe Experience Manager

Apache · Sling

The Servlets Post component 2.3.6 in Apache Sling, as bundled in Adobe Experience Manager 5.6.1, 6.0.0 and 6.1.0, exposes sensitive information to remote attackers through unspecified vectors. The flaw is a CWE-200 information exposure reachable over the network without credentials, so any reachable AEM instance running the affected Sling version is at risk. The record does not describe the exact request or data leaked, so defenders must rely on the vendor advisory and patch rather than a precise trigger.

7.5 CVSS 3.0 High EPSS 51% · top 1.1% CWE-200 · Information exposure
7.5CVSS 3.0 base score, v2 7.8
51%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
10References
17 Jun 2026Last modified by NVD

Description

The Servlets Post component 2.3.6 in Apache Sling, as used in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0, allows remote attackers to obtain sensitive information via unspecified vectors.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityUnauthenticated remote information disclosure with high confidentiality impact, public exploit code and very high EPSS, though no KEV listing or active exploitation is documented.

What it is

The Servlets Post component 2.3.6 in Apache Sling, as bundled in Adobe Experience Manager 5.6.1, 6.0.0 and 6.1.0, exposes sensitive information to remote attackers through unspecified vectors. The flaw is a CWE-200 information exposure reachable over the network without credentials, so any reachable AEM instance running the affected Sling version is at risk. The record does not describe the exact request or data leaked, so defenders must rely on the vendor advisory and patch rather than a precise trigger.

Impact

An unauthenticated remote attacker can read sensitive information from the affected AEM/Sling deployment, with high confidentiality impact and no integrity or availability effect. The specific data exposed is not stated in the record.

Attack surface

Reachable over the network via HTTP against the Sling Servlets Post component; the CVSS vector shows no privileges and no user interaction required. No authentication is needed per the vector, though the exact endpoint is not specified.

Exploitation

Not listed in CISA KEV and no ransomware association is documented. EPSS is high (0.51151, ~98.9th percentile) and a public Exploit-DB entry (39435) plus Packet Storm and Full Disclosure posts exist, indicating public proof-of-concept material is available.

What to do

  • Apply the Adobe Experience Manager fix referenced in Adobe advisory APSB16-05 (helpx.adobe.com/security/products/experience-manager/apsb16-05.html) or upgrade the bundled Apache Sling Servlets Post component past 2.3.6.
  • If immediate patching is not possible, restrict network access to AEM/Sling instances to trusted networks and block unnecessary exposure of the Servlets Post endpoints.
  • Review and disable or restrict the Servlets Post component if it is not required by the application.
  • Monitor vendor advisories for the affected AEM versions (5.6.1, 6.0.0, 6.1.0) and confirm which deployments still run them.

Detection

  • Inspect web/proxy logs for anomalous requests to Sling Servlets Post paths returning larger-than-normal or unexpected response bodies.
  • Alert on unauthenticated access to Sling servlet endpoints from external or untrusted source addresses.
  • Compare responses from the affected component against expected content to identify unexpected data disclosure.
  • Track AEM/Sling version banners and asset inventories to flag hosts still running the affected versions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-0956 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2026-19232Adobe experience manager incorrect authorization vulnerabilityAdobe Experience Manager is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the …EPSS 0.59%9.8CVE-2025-49533Adobe Experience Manager untrusted deserialization enables remote code executionAdobe Experience Manager (MS) versions 6.5.23.0 and earlier contain a deserialization of untrusted data flaw (CWE-502) that can lead to arbitrary cod…EPSS 53%analysed9.8CVE-2024-26029Adobe experience manager improper access control vulnerabilityAdobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature…EPSS 0.89%9.8CVE-2021-40722Adobe experience manager xml external entity (xxe) vulnerabilityAEM Forms Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by an XML External Entity (XXE) injection vulnerability that c…EPSS 3.3%9.8CVE-2019-8088Adobe experience manager command injection vulnerabilityAdobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a command injection vulnerability. Successful exploitation could lead to arbitrary code …EPSS 5.8%9.8CVE-2019-7964Adobe experience manager vulnerabilityAdobe Experience Manager versions 6.5, and 6.4 have an authentication bypass vulnerability. Successful exploitation could lead to remote code executi…EPSS 10%9.8CVE-2017-3108Adobe experience manager unrestricted file upload vulnerabilityAdobe Experience Manager 6.2 and earlier has a malicious file execution vulnerability.EPSS 8.6%9.8CVE-2016-6798Apache sling xml external entity (xxe) vulnerabilityIn the XSS Protection API module before 1.0.12 in Apache Sling, the method XSS.getValidXML() uses an insecure SAX parser to validate the input string…EPSS 3.7%

Source: NIST National Vulnerability Database (record CVE-2016-0956), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.